Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1083 File and Directory Discovery |
MalwareSkidmap | Skidmap has checked for the existence of specific files including |
| T1083 File and Directory Discovery |
MalwareOkrum | Okrum has used DriveLetterView to enumerate drive information. |
| T1083 File and Directory Discovery |
MalwareConti | Conti can discover files on a local system. |
| T1083 File and Directory Discovery |
MalwareSameCoin | SameCoin can list all system files and can avoid wiping specific directories such as Program Files, Windows, and Users. |
| T1083 File and Directory Discovery |
MalwareRaspberry Robin | Raspberry Robin will check to see if the initial executing script is located on the user's Desktop as an anti-analysis check. |
| T1083 File and Directory Discovery |
MalwareMispadu | Mispadu searches for various filesystem paths to determine what banking applications are installed on the victim’s machine. |
| T1083 File and Directory Discovery |
MalwareMegazord | Megazord can ignore specified directories for encryption. |
| T1083 File and Directory Discovery |
MalwareDiavol | Diavol has a command to traverse the files and directories in a given path. |
| T1083 File and Directory Discovery |
MalwareDoki | Doki has resolved the path of a process PID to use as a script argument. |
| T1083 File and Directory Discovery |
MalwareSiloscape | Siloscape searches for the Kubernetes config file and other related files using a regular expression. |
| T1083 File and Directory Discovery |
MalwareBlackCat | BlackCat can enumerate files for encryption. |
| T1083 File and Directory Discovery |
MalwareFysbis | Fysbis has the ability to search for files. |
| T1083 File and Directory Discovery |
MalwareMarkiRAT | MarkiRAT can look for files carrying specific extensions such as: .rtf, .doc, .docx, .xls, .xlsx, .ppt, .pptx, .pps, .ppsx, .txt, .gpg, .pkr, .kdbx, .key, and .jpb. |
| T1083 File and Directory Discovery |
MalwareKazuar | Kazuar finds a specified directory, lists the files and metadata about those files. |
| T1083 File and Directory Discovery |
MalwareNETEAGLE | NETEAGLE allows adversaries to enumerate and modify the infected host's file system. It supports searching for directories, creating directories, listing directory contents, reading and writing to files, retrieving file attributes, and retrieving volume information. |
| T1083 File and Directory Discovery |
MalwarePOORAIM | POORAIM can conduct file browsing. |
| T1083 File and Directory Discovery |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP has the ability to enumerate directories for files that match a set list. |
| T1083 File and Directory Discovery |
MalwareFatDuke | FatDuke can enumerate directories on target machines. |
| T1083 File and Directory Discovery |
MalwareBlackEnergy | BlackEnergy gathers a list of installed apps from the uninstall program Registry. It also gathers registered mail, browser, and instant messaging clients from the Registry. BlackEnergy has searched for given file types. |
| T1083 File and Directory Discovery |
MalwarezwShell | zwShell can browse the file system. |
| T1083 File and Directory Discovery |
MalwareRising Sun | Rising Sun can enumerate information about files from the infected system, including file size, attributes, creation time, last access time, and write time. Rising Sun can enumerate the compilation timestamp of Windows executable files. |
| T1083 File and Directory Discovery |
MalwareNotPetya | NotPetya searches for files ending with dozens of different file extensions prior to encryption. |
| T1083 File and Directory Discovery |
MalwareShimRat | ShimRat can list directories. |
| T1083 File and Directory Discovery |
MalwareObliqueRAT | ObliqueRAT has the ability to recursively enumerate files on an infected endpoint. |
| T1083 File and Directory Discovery |
MalwareSHOTPUT | SHOTPUT has a command to obtain a directory listing. |
| T1083 File and Directory Discovery |
MalwareAvaddon | Avaddon has searched for specific files prior to encryption. |
| T1083 File and Directory Discovery |
MalwareXAgentOSX | XAgentOSX contains the readFiles function to return a detailed listing (sometimes recursive) of a specified directory. XAgentOSX contains the showBackupIosFolder function to check for IOS device backups by running |
| T1083 File and Directory Discovery |
MalwareChina Chopper | China Chopper's server component can list directory contents. |
| T1083 File and Directory Discovery |
MalwareLightSpy | LightSpy uses the `NSFileManager` to move, create and delete files. LightSpy can also use the assembly `bt` instruction to determine a file's executable permissions. |
| T1083 File and Directory Discovery |
MalwareCheerscrypt | Cheerscrypt can search for log and VMware-related files with .log, .vmdk, .vmem, .vswp, and .vmsn extensions. |
| T1083 File and Directory Discovery |
MalwareKeyBoy | KeyBoy has a command to launch a file browser or explorer on the system. |
| T1083 File and Directory Discovery |
MalwareMiniDuke | MiniDuke can enumerate local drives. |
| T1083 File and Directory Discovery |
MalwarePteranodon | Pteranodon identifies files matching certain file extension and copies them to subdirectories it created. |
| T1083 File and Directory Discovery |
MalwareBeaverTail | BeaverTail has searched for .ldb and .log files stored in browser extension directories for collection and exfiltration. |
| T1083 File and Directory Discovery |
MalwareROKRAT | ROKRAT has the ability to gather a list of files and directories on the infected system. |
| T1083 File and Directory Discovery |
MalwareBabuk | Babuk has the ability to enumerate files on a targeted system. |
| T1083 File and Directory Discovery |
MalwareExbyte | Exbyte enumerates all document files on an infected machine, then creates a summary of these items including filename and directory location prior to exfiltration to cloud hosting services. |
| T1083 File and Directory Discovery |
MalwareDarkWatchman | DarkWatchman has the ability to enumerate file and folder names. |
| T1083 File and Directory Discovery |
MalwareBlackMould | BlackMould has the ability to find files on the targeted system. |
| T1083 File and Directory Discovery |
MalwarePACEMAKER | PACEMAKER can parse `/proc/"process_name"/cmdline` to look for the string `dswsd` within the command line. |
| T1083 File and Directory Discovery |
MalwareBBSRAT | BBSRAT can list file and directory information. |
| T1083 File and Directory Discovery |
MalwarePlugX | PlugX has a module to enumerate drives and find files recursively. PlugX has also checked the path from which it is running for specific parameters prior to execution. |
| T1083 File and Directory Discovery |
MalwareBisonal | Bisonal can retrieve a file listing from the system. |
| T1083 File and Directory Discovery |
MalwareMultiLayer Wiper | MultiLayer Wiper generates a list of all files and paths on the fixed drives of an infected system, enumerating all files on the system except specific folders defined in a hardcoded list. |
| T1083 File and Directory Discovery |
MalwareDustySky | DustySky scans the victim for files that contain certain keywords and document types including PDF, DOC, DOCX, XLS, and XLSX, from a list that is obtained from the C2 as a text file. It can also identify logical drives for the infected machine. |
| T1083 File and Directory Discovery |
MalwareRemsec | Remsec is capable of listing contents of folders on the victim. Remsec also searches for custom network encryption software on victims. |
| T1083 File and Directory Discovery |
MalwareRover | Rover automatically searches for files on local drives based on a predefined list of file extensions. |
| T1083 File and Directory Discovery |
MalwareEpic | Epic recursively searches for all .doc files on the system and collects a directory listing of the Desktop, %TEMP%, and %WINDOWS%\Temp directories. |
| T1083 File and Directory Discovery |
MalwarePeppy | Peppy can identify specific files for exfiltration. |
| T1083 File and Directory Discovery |
MalwareCuba | Cuba can enumerate files by using a variety of functions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.